Swift-Attack: detect common macOS post-exploitation methods
Swift-Attack
Unit tests for blue teams to aid with building detections for some common macOS post-exploitation methods. I have included some post-exploitation examples using both command line history and on-disk binaries (which should be easier for detection) as well as post-exploitation examples using API calls only (which will be more difficult for detection). The post-exploitation examples included here are not all-encompassing. Instead, these are just some common examples that I thought would be useful to conduct unit tests around. I plan to continue to add to this project over time with additional unit tests.
All of these tests run locally and return results to stdout (i.e., Swift-Attack does not connect to a server).
Unit Tests Included:
- Prompt using osascript binary
- Prompt via API calls
- Clipboard dump using osascript binary
- Clipboard dump using API calls
- Screenshot using screencapture binary
- Screenshot using API calls
- Shell commands
- Dumping zsh history
- Security tool enumeration
- Grabbing system info using osascript binary
- Grabbing system info via API calls
- Dumping ssh, aws, gcp, and azure keys on disk
- Dumping browser history (Chrome, Safari, Firefox)
- Dumping Quarantine history
- Office Macro: I included a simple office macro that connects to localhost. Note: the macro will invoke curl to make a GET request using python to http://127.0.0.1/testing when executed by clicking the “Enable Macros” button. This will allow you to test detections for parent-child relationships around macro execution. Note: this simple test does not include any obfuscation, since the test is really more geared towards parent-child relationships. You can use another repo of mine at https://github.com/cedowens/MacC2 to test with obfuscated macros. To use, just simply paste the contents of “macro.txt” into an office Doc, save as a macro-enabled document or as 97-2004 document format (ex: .doc, .xls, etc.), and click “Enable Macros” when opening the doc to execute.
- Installer Package: I included TestInstaller.pkg file to test for detections around a basic installer package. This installer package includes a preinstall script which runs in bash and drops com.simple.agent.plist to /Library/LaunchDaemons/ and drops test.js (simple popup prompt) to /Library/Application Support/. The com.simple.agent.plist file simply runs osascript against /Library/Application Support/test.js. It also includes a postinstall script which runs in bash and loads the com.simple.agent.plis using launchctl load. While holding the Control button click Open on TestInstaller.pkg to run it. TestInstaller.pkg will drop the aforementioned files as root.
- CVE-2021-30657 Bypass Payloads: Two sample payloads (both make curl requests to localhost when detonated) to test two different types of payloads that abuse cve-2021-30657. More info here
Install & Use
Copyright (c) 2021, Cedric Owens
All rights reserved.